imPC@ndo EN

Vulnerabilità Cisco

6642 CVE

CVE-2022-20783
Alta 7.5

A vulnerability in the packet processing functionality of Cisco TelePresence Collaboration Endpoint (CE) Software and Cisco RoomOS Software could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition on an affected device. This…

cisco roomos · cisco telepresence_collaboration_endpoint
0.01EPSS
CVE-2015-6356
Media 4.3

Cross-site scripting (XSS) vulnerability in the WeChat page in Cisco Social Miner 10.0(1) allows remote attackers to inject arbitrary web script or HTML via unspecified vectors, aka Bug ID CSCuw60212.

cisco socialminer
0.01EPSS
CVE-2014-3325
Media 4.3

Multiple cross-site scripting (XSS) vulnerabilities in Cisco Unified Customer Voice Portal (CVP) allow remote attackers to inject arbitrary web script or HTML via a crafted parameter, aka Bug IDs CSCuh61711, CSCuh61720, CSCuh61723, CSCuh61726, CSCuh61727, CSCu…

cisco unified_customer_voice_portal
0.01EPSS
CVE-2014-3265
Media 4.3

Cross-site scripting (XSS) vulnerability in the Auto Update Server (AUS) web framework in Cisco Security Manager 4.2 and earlier allows remote attackers to inject arbitrary web script or HTML via an unspecified parameter, aka Bug ID CSCuo06900.

cisco security_manager
0.01EPSS
CVE-2013-1178
Alta 8.3

Multiple buffer overflows in the Cisco Discovery Protocol (CDP) implementation in Cisco NX-OS on Nexus 7000 devices 4.x and 5.x before 5.2(4) and 6.x before 6.1(1), Nexus 5000 and 5500 devices 4.x and 5.x before 5.1(3)N1(1), Nexus 4000 devices before 4.1(2)E1(…

cisco cg-os · cisco connected_grid_router_1000 · cisco mds_9000 · cisco nexus_1000v · e altri 23
0.01EPSS
CVE-2015-6365
Media 4.0

Cisco IOS 15.2(04)M and 15.4(03)M lets physical-interface ACLs supersede virtual PPP interface ACLs, which allows remote authenticated users to bypass intended network-traffic restrictions in opportunistic circumstances by using PPP, aka Bug ID CSCur61303.

cisco ios
0.01EPSS
CVE-2015-6347
Media 4.0

The Solution Engine in Cisco Secure Access Control Server (ACS) 5.7(0.15) allows remote authenticated users to bypass intended RBAC restrictions, and create a dashboard or portlet, by visiting an unspecified web page.

cisco secure_access_control_server
0.01EPSS
CVE-2021-1387
Alta 8.6

A vulnerability in the network stack of Cisco NX-OS Software could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition on an affected device. This vulnerability exists because the software improperly releases resources when i…

cisco nx-os · cisco unified_computing_system
0.01EPSS
CVE-2019-1907
Alta 8.8

A vulnerability in the web server of Cisco Integrated Management Controller (IMC) could allow an authenticated, remote attacker to set sensitive configuration values and gain elevated privileges. The vulnerability is due to improper handling of substring compa…

cisco integrated_management_controller_supervisor · cisco unified_computing_system
0.01EPSS
CVE-2015-0602
Media 5.0

The mobility extension on Cisco Unified IP 9900 phones with firmware 9.4(.1) and earlier allows remote attackers to obtain sensitive information by sniffing the network, aka Bug ID CSCuq12117.

cisco unified_ip_phones_9900_series_firmware
0.01EPSS
CVE-2014-8034
Media 5.0

Cisco WebEx Meetings Server 1.5 presents the same CAPTCHA challenge for each login attempt, which makes it easier for remote attackers to obtain access via a brute-force approach of guessing usernames, aka Bug ID CSCuj40321.

cisco webex_meetings_server
0.01EPSS
CVE-2013-6970
Media 5.0

Cisco WebEx Meeting Center allows remote attackers to obtain sensitive information by reading verbose error messages within server responses, aka Bug ID CSCul35928.

cisco webex_meeting_center
0.01EPSS
CVE-2015-6348
Media 4.0

The report-generation web interface in the Solution Engine in Cisco Secure Access Control Server (ACS) 5.7(0.15) allows remote authenticated users to bypass intended RBAC restrictions, and read report or status information, by visiting an unspecified web page.…

cisco secure_access_control_server
0.01EPSS
CVE-2015-6344
Media 4.0

The web-based GUI in Cisco Adaptive Security Appliance (ASA) CX Context-Aware Security 9.3(4.1.11) allows remote authenticated users to bypass intended access restrictions and obtain sensitive user information via an unspecified HTTP request, aka Bug ID CSCuv7…

cisco asa_cx_context-aware_security_software
0.01EPSS
CVE-2013-5551
Media 6.3

Cisco Adaptive Security Appliance (ASA) Software, when certain same-security-traffic and management-access options are enabled, allows remote authenticated users to cause a denial of service (stack overflow and device reload) by using the clientless SSL VPN po…

cisco adaptive_security_appliance_software
0.01EPSS
CVE-2019-1765
Alta 8.1

A vulnerability in the web-based management interface of Session Initiation Protocol (SIP) Software for Cisco IP Phone 8800 Series could allow an authenticated, remote attacker to write arbitrary files to the filesystem. The vulnerability is due to insufficien…

cisco ip_conference_phone_8832_firmware · cisco ip_phone_8800_firmware · cisco ip_phone_8821-ex_firmware · cisco ip_phone_8821_firmware
0.01EPSS
CVE-1999-0889
Alta 7.5

Cisco 675 routers running CBOS allow remote attackers to establish telnet sessions if an exec or superuser password has not been set.

cisco 675_router
0.01EPSS
CVE-2021-1245
Media 6.5

Cisco Finesse and Cisco Unified CVP OpenSocial Gadget Editor Cross-Site Scripting Vulnerability A vulnerability in the web-based management interface of Cisco Finesse and Cisco Unified CVP could allow an unauthenticated, remote attacker to conduct a cross-s…

cisco finesse
0.01EPSS
CVE-2015-0604
Media 5.0

The web framework on Cisco Unified IP 9900 phones with firmware 9.4(.1) and earlier allows remote attackers to upload files to arbitrary locations on a phone's filesystem via crafted HTTP requests, aka Bug ID CSCup90424.

cisco unified_ip_phones_9951_firmware · cisco unified_ip_phones_9971_firmware
0.01EPSS
CVE-1999-1100
Alta 7.5

Cisco PIX Private Link 4.1.6 and earlier does not properly process certain commands in the configuration file, which reduces the effective key length of the DES key to 48 bits instead of 56 bits, which makes it easier for an attacker to find the proper key via…

cisco pix_private_link
0.01EPSS
CVE-2020-3482
Media 6.5

A vulnerability in the Traversal Using Relays around NAT (TURN) server component of Cisco Expressway software could allow an unauthenticated, remote attacker to bypass security controls and send network traffic to restricted destinations. The vulnerability is …

cisco expressway · cisco telepresence_video_communication_server
0.01EPSS
CVE-2020-3399
Alta 8.6

A vulnerability in the Control and Provisioning of Wireless Access Points (CAPWAP) protocol processing of Cisco IOS XE Software for Cisco Catalyst 9800 Series Wireless Controllers could allow an unauthenticated, remote attacker to cause a denial of service (Do…

cisco ios_xe
0.01EPSS
CVE-2019-1905
Media 5.8

A vulnerability in the GZIP decompression engine of Cisco AsyncOS Software for Cisco Email Security Appliance (ESA) could allow an unauthenticated, remote attacker to bypass configured content filters on the device. The vulnerability is due to improper validat…

cisco email_security_appliance
0.01EPSS
CVE-2015-6350
Media 6.5

SQL injection vulnerability in the web framework in Cisco Prime Service Catalog 11.0 allows remote authenticated users to execute arbitrary SQL commands via unspecified vectors, aka Bug ID CSCuw50843.

cisco prime_service_catalog
0.01EPSS
CVE-2015-6345
Media 6.5

SQL injection vulnerability in the Solution Engine in Cisco Secure Access Control Server (ACS) 5.7(0.15) allows remote authenticated users to execute arbitrary SQL commands via a crafted URL, aka Bug ID CSCuw24700.

cisco secure_access_control_server
0.01EPSS